13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
|
# File 'lib/puppet_x/consul/http_client.rb', line 13
def self.build(uri, options = {})
http = Net::HTTP.new(uri.host, uri.port)
return http unless uri.is_a?(URI::HTTPS)
http.use_ssl = true
http.verify_mode = OpenSSL::SSL::VERIFY_PEER
http.verify_hostname = true
http.ca_file = options[:ca_file] if options[:ca_file]
http.ca_path = options[:ca_path] if options[:ca_path]
if options[:client_cert] || options[:client_key]
raise Puppet::Error, 'Consul client_cert and client_key must be supplied together' unless options[:client_cert] && options[:client_key]
certificates = File.read(options[:client_cert]).scan(%r{-----BEGIN CERTIFICATE-----.*?-----END CERTIFICATE-----}m)
raise Puppet::Error, 'Consul client_cert does not contain a PEM certificate' if certificates.empty?
http.cert = OpenSSL::X509::Certificate.new(certificates.shift)
http. = certificates.map { |pem| OpenSSL::X509::Certificate.new(pem) }
http.key = OpenSSL::PKey.read(File.read(options[:client_key]), '')
raise Puppet::Error, 'Consul client_key does not match client_cert' unless http.cert.check_private_key(http.key)
end
http
end
|